Privacy Policy
Last updated: October 1, 2026 · FoodTracker by PatakoLabs
The short version: Your meal photos and full diary stay on your device (and your personal iCloud if you enable sync). We do not sell your data and we do not create advertising profiles. Photos leave the device only for AI food recognition. Separately, the app sends product and usage events under a random id (purchase funnel, analysis reliability, and aggregated meal nutrition metrics such as ingredient names and calorie/macro totals) so we can improve the product — never your name, email, or photos.
1. Data That Stays on Your Device
The following data is stored locally using Apple's SwiftData framework and is not uploaded to PatakoLabs as food or health content:
- Meal entries, food items, and nutritional logs
- Weight entries and historical records
- Water intake (glasses)
- Fasting windows
- Saved meal photos (stored in the app's Documents directory)
- Your custom local food database
- Daily calorie and macro goals
- App preferences and settings
API keys you provide (OpenAI, USDA) are stored in the device Keychain with kSecAttrAccessibleAfterFirstUnlock protection. Keychain data is not synced to iCloud and is deleted when you uninstall the app.
2. Data That Leaves Your Device
We send the minimum data required to provide core features and to operate the App Store subscription. Here is an exhaustive list:
| What | Where | Why |
|---|---|---|
| Meal photo (compressed JPEG) | OpenAI API or PatakoLabs API (patakolabs.com) | AI food recognition |
| Food name (text query) | USDA FoodData Central | Nutrition data lookup |
| Food name (text query) | Open Food Facts | Nutrition data fallback |
| Opaque device token (hashed on server) | PatakoLabs API | Device registration and free-tier quota |
| Apple Sign in identifier / subscription transaction id | PatakoLabs API | Authenticate free or Premium access |
| Random analytics id (UUID) and product events | PatakoLabs API → PostHog (EU) | Purchase funnel, unlocks, analysis reliability, and aggregated meal nutrition metrics |
| Voice meal transcript (text only) | PatakoLabs API (OpenRouter / OpenAI) | Parse spoken food descriptions into meal items (shares AI analysis quota) |
| Active / resting energy (optional) | Apple Health on device | Expand today’s calorie budget and show energy breakdown — not uploaded as Health samples |
| Approximate app foreground time | PatakoLabs API (and Apple, only with consent) | Answer Apple consumption / refund requests |
| Optional feedback message and contact email you type | PatakoLabs support inbox | Respond to support requests you submit |
We do not transmit your name, phone number, location, advertising identifier (IDFA), meal logs, weight history, or food diary contents for analytics.
3. Meal Photo Processing
When you photograph a meal for AI analysis, the image is compressed to JPEG and sent to one of two destinations depending on your configuration:
- Bring Your Own Key (BYOK) mode: The photo is sent directly from your device to the OpenAI API using your personal API key. PatakoLabs never sees the image.
- Free / Premium mode: The photo is sent to the PatakoLabs API proxy, which forwards it to an AI provider (OpenRouter or OpenAI) for processing. The image is not stored on our servers — it is forwarded in real time and discarded immediately after the response is returned.
In both cases, only food names and estimated portion sizes are returned. No image data is stored by our backend. If an analysis fails after retries, we may record a short failure reason code (for example rate_limited) without the photo or food text.
4. iCloud Sync
If you have iCloud enabled for FoodTracker on your device, the following data is synced to your personal iCloud account via Apple CloudKit:
- Meal entries and food items
- Weight entries
- Photo entries (full image and thumbnail)
This sync is managed entirely by Apple. Data is encrypted in transit and at rest using your iCloud account credentials. PatakoLabs has no access to your iCloud data. You can disable iCloud sync for FoodTracker at any time in your device's Settings app.
5. Nutrition Data Sources
To find nutritional information for identified foods, the app sends text search queries (food names only) to:
- USDA FoodData Central (fdc.nal.usda.gov) — U.S. Department of Agriculture public nutrition database
- Open Food Facts (world.openfoodfacts.org) — open-source food product database
Only food name text is sent to these services. No images, device identifiers, or personal information are included in nutrition queries. Search results are cached in memory for up to one hour and are not persisted to disk.
6. Device and Account Identifiers
FoodTracker uses two opaque identifiers on device:
- Device registration token — derived for backend quota. The server stores a one-way hash. It is not an advertising identifier and resets if you remove PatakoLabs apps from the device.
- Analytics / StoreKit account token — a random UUID created on first launch, stored in the Keychain, and also passed to Apple as
appAccountTokenwhen you purchase. The same UUID is used as the analytics person id so App Store refunds can be joined to in-app purchase and reliability events.
If you Sign in with Apple for the free tier, Apple’s user identifier is used to mint a short-lived access token. We do not receive your Apple ID email unless you choose to share it with Apple’s Sign in flow.
7. Subscriptions and Payments
Subscription purchases are handled entirely by Apple through StoreKit 2. PatakoLabs does not collect, process, or store payment card numbers or your Apple ID password. We receive subscription status (and App Store Server Notifications such as renewals or refunds) so we can unlock Premium and adjust AI analysis quotas. Free tier: lifetime analyses with a daily cap; Premium: unlimited while the subscription is active.
When Apple asks for consumption information after a refund request, we may send Apple approximate hours of app use, how long the account has existed, and a refund preference. Fields that need your permission are only sent when you consent in the in-app prompt shown after auto-renew is turned off.
8. Product Analytics
FoodTracker does not embed advertising SDKs, crash reporters, or third-party analytics libraries in the iOS binary. Product events are sent to the PatakoLabs API, which may forward an allowlisted set to PostHog hosted in the EU for operational analytics.
Events we may collect (always under the random analytics id, never under your name):
- Paywall viewed
- Purchase tapped / succeeded / failed (with a short reason such as cancelled or pending)
- Premium unlocked
- Vision analysis completed or failed (duration, attempt count, route, short reason codes)
- Re-analyze taps (when you ask for another AI pass)
- Meal logged and ingredient logged (ingredient name, grams, calories, and macro totals; meal type / logging source)
- Optional cancel/refund feedback when auto-renew is disabled
These events do not include meal photos, raw audio, weight values, or the free-text body of Settings → Send Feedback beyond what you explicitly submit. Ingredient names are normalized plain-language food labels used for product quality (popular foods, portion accuracy), not advertising profiles.
Water glasses, weight history, and local food database edits remain on-device (and in your iCloud if sync is enabled).
The marketing website at patakolabs.com has a separate cookie banner for optional web analytics. That website consent does not control the in-app product events described here.
9. Children's Privacy
FoodTracker is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided data through the app, please contact us and we will take steps to remove it.
10. Data Retention
- On-device data: Persists until you delete it within the app or uninstall the app.
- iCloud data: Managed by your Apple ID settings. Deleting the app does not automatically remove iCloud data.
- Backend quota and auth: Device or Apple subject records and quota counters. No meal diaries or photos are stored as content on our servers.
- Product analytics: Event records and the link between the random analytics id and Apple’s original transaction id, retained according to our PostHog project settings and operational logs, only as long as needed to investigate purchases, refunds, and reliability.
11. Your Rights
You control most of your data on device and in iCloud:
- Access: Meal and weight data is visible within the app at all times.
- Delete: Delete individual meals, photos, or weight entries from the app. Uninstall to remove local Keychain and on-device data for this installation.
- Portability: iCloud data is accessible through your Apple ID across your devices.
- Opt out of sync: Disable iCloud for FoodTracker in Settings to keep diary data strictly on-device.
- Refund usage sharing: Decline the optional toggle when we ask whether FoodTracker may tell Apple how long you used the app.
- Server-side analytics or quota records: Email us (below) with enough detail to identify your installation or purchase; we will delete what we control where legally and technically possible.
12. Security
- All network communication uses HTTPS (TLS 1.2+)
- API keys and the analytics id are stored in the iOS Keychain (hardware-backed on supported devices)
- Backend authentication uses short-lived JWTs after Sign in with Apple or Apple subscription verification
- iCloud data is encrypted with your Apple ID credentials
- No payment card data is stored by PatakoLabs
13. Changes to This Policy
We will update this page when the policy changes. Material changes will be noted in the app's release notes. Continued use of FoodTracker after changes constitutes acceptance of the updated policy.
14. Contact
For privacy questions or data requests:
PatakoLabs<br> Email: kikov79@icloud.com<br> Policy URL: https://patakolabs.com/legal/foodtracker/privacy-policy